🟠 High — Wysokie podatności CVE (CVSS 7.0–8.9) wymagające pilnego łatania. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟡 Medium ⚪ Low
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.4% EPSS
siemensexploitrce 2017-03-17
CVE-2016-6277 🔴 Łataj teraz KEV
network

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 b…

8.8 CVSS
94.3% EPSS
netgearexploit 2016-12-14
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8 CVSS
94.3% EPSS
microsoftrce 2012-04-10
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2011-0611 🔴 Łataj teraz KEV

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.…

8.8 CVSS
93.7% EPSS
adobedosexploit 2011-04-13
CVE-2010-1871 🔴 Łataj teraz KEV

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe…

8.8 CVSS
93.6% EPSS
netapp 2010-08-05
CVE-2009-0927 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab o…

8.8 CVSS
93.3% EPSS
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2014-0322 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a scrip…

8.8 CVSS
93.2% EPSS
microsoftexploit 2014-02-14
CVE-2012-1889 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8 CVSS
93.1% EPSS
microsoftdos 2012-06-13
CVE-2015-2051 🔴 Łataj teraz KEV
network

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

8.8 CVSS
93.0% EPSS
dlinkexploit 2015-02-23
CVE-2016-3714 🔴 Łataj teraz KEV
os

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact…

8.4 CVSS
94.0% EPSS
canonical 2016-05-05
CVE-2015-2426 🔴 Łataj teraz KEV
appscloud

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind…

8.8 CVSS
91.8% EPSS
microsoftexploit 2015-07-20
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8 CVSS
91.5% EPSS
microsoftrce 2012-08-15
CVE-2012-4792 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2…

8.8 CVSS
91.4% EPSS
microsoft 2012-12-30
CVE-2016-6366 🔴 Łataj teraz KEV
network

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote a…

8.8 CVSS
91.4% EPSS
CVE-2013-2551 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during …

8.8 CVSS
91.3% EPSS
microsoft 2013-03-11
CVE-2017-12617 🔴 Łataj teraz KEV
appsos

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal…

8.1 CVSS
94.4% EPSS
oracleexploit 2017-10-04
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2017-12615 🔴 Łataj teraz KEV
os

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci…

8.1 CVSS
94.2% EPSS
redhatexploit 2017-09-19
CVE-2014-0502 🔴 Łataj teraz KEV
os

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR S…

8.8 CVSS
90.6% EPSS
redhatexploit 2014-02-21
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2009-3953 🔴 Łataj teraz KEV

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, …

8.8 CVSS
90.5% EPSS
adobe 2010-01-13
CVE-2017-5521 🔴 Łataj teraz KEV
network

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to…

8.1 CVSS
93.8% EPSS
netgearexploit 2017-01-17
CVE-2016-7201 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
90.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2014-6278 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated …

8.8 CVSS
90.1% EPSS
gnu 2014-09-30
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8 CVSS
90.1% EPSS
zyxelexploitrce 2017-04-06
CVE-2014-6324 🔴 Łataj teraz KEV
appscloud

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows re…

8.8 CVSS
89.9% EPSS
microsoft 2014-11-18
CVE-2017-11882 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by fa…

7.8 CVSS
94.4% EPSS
microsoftexploit 2017-11-15
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2017-6334 🔴 Łataj teraz KEV
network

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a diffe…

8.8 CVSS
89.2% EPSS
netgearexploit 2017-03-06
CVE-2015-8651 🔴 Łataj teraz KEV

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe A…

8.8 CVSS
89.1% EPSS
adobe 2015-12-28
CVE-2017-6736 🔴 Łataj teraz KEV
network

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

8.8 CVSS
89.0% EPSS
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2010-3333 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers…

7.8 CVSS
93.8% EPSS
CVE-2008-2992 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argum…

7.8 CVSS
93.7% EPSS
CVE-2015-1641 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office …

7.8 CVSS
93.6% EPSS
microsoft 2015-04-14
CVE-2010-0188 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

7.8 CVSS
93.5% EPSS
adobedos 2010-02-22
CVE-2015-2545 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

7.8 CVSS
93.3% EPSS
microsoftexploit 2015-09-09
CVE-2014-1761 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web…

7.8 CVSS
93.3% EPSS
microsoftdos 2014-03-25
CVE-2011-3402 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 …

8.8 CVSS
88.3% EPSS
microsoft 2011-11-04
CVE-2012-4969 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in …

8.1 CVSS
91.8% EPSS
microsoft 2012-09-18
CVE-2013-3897 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via c…

8.8 CVSS
88.2% EPSS
microsoftdos 2013-10-09
CVE-2016-7200 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
88.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2007-5659 🔴 Łataj teraz KEV

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be su…

7.8 CVSS
93.1% EPSS
CVE-2013-0074 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight app…

7.8 CVSS
93.0% EPSS
microsoft 2013-03-13
CVE-2012-0754 🔴 Łataj teraz KEV

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbit…

8.1 CVSS
91.5% EPSS
adobedos 2012-02-16
CVE-2014-0160 🔴 Łataj teraz KEV

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa…

7.5 CVSS
94.5% EPSS
mitelexploit 2014-04-07
CVE-2017-10271 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitab…

7.5 CVSS
94.4% EPSS
oracleexploit 2017-10-19
CVE-2017-8291 🔴 Łataj teraz KEV
os

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program…

7.8 CVSS
92.9% EPSS
redhatexploit 2017-04-27
CVE-2009-4324 🔴 Łataj teraz KEV

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code v…

7.8 CVSS
92.9% EPSS
adobeexploit 2009-12-15
CVE-2010-1297 🔴 Łataj teraz KEV

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute…

7.8 CVSS
92.8% EPSS
adobedosexploit 2010-06-08
CVE-2013-1347 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited…

8.8 CVSS
87.7% EPSS
microsoftexploit 2013-05-05
CVE-2013-3906 🔴 Łataj teraz KEV
appscloud

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execu…

7.8 CVSS
92.6% EPSS
microsoftexploit 2013-11-06
CVE-2017-0261 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
92.5% EPSS
microsoftrce 2017-05-12
CVE-2017-3506 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to e…

7.4 CVSS
94.4% EPSS
oracle 2017-04-24
CVE-2013-0640 🔴 Łataj teraz KEV
os

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as expl…

7.8 CVSS
92.3% EPSS
redhatdos 2013-02-14
CVE-2020-5849 🔴 Łataj teraz KEV

Unraid 6.8.0 allows authentication bypass.

7.5 CVSS
93.8% EPSS
CVE-2010-2568 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF sho…

7.8 CVSS
92.1% EPSS
microsoftexploit 2010-07-22
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2011-0609 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle)…

7.8 CVSS
92.1% EPSS
adobedos 2011-03-15
CVE-2017-0037 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to…

8.1 CVSS
90.5% EPSS
microsoftexploit 2017-02-26
CVE-2013-3918 🔴 Łataj teraz KEV
appscloud

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows …

8.8 CVSS
87.0% EPSS
microsoftdos 2013-11-12
CVE-2017-12637 🔴 Łataj teraz KEV

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string…

7.5 CVSS
93.5% EPSS
sappath-traversal 2017-08-07
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2012-1535 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application cra…

7.8 CVSS
91.6% EPSS
redhatdos 2012-08-15
CVE-2016-6415 🔴 Łataj teraz KEV
network

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information…

7.5 CVSS
93.0% EPSS
cisco 2016-09-19
CVE-2009-3129 🔴 Łataj teraz KEV
appscloud

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili…

7.8 CVSS
91.2% EPSS
microsoftexploit 2009-11-11
CVE-2017-0147 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

7.5 CVSS
92.4% EPSS
siemensexploit 2017-03-17
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2014-6352 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
90.7% EPSS
microsoft 2014-10-22
CVE-2010-2883 🔴 Łataj teraz KEV

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (applic…

7.3 CVSS
93.2% EPSS
CVE-2016-0099 🔴 Łataj teraz KEV
appscloud

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly …

7.8 CVSS
90.4% EPSS
CVE-2010-3962 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an…

8.1 CVSS
88.9% EPSS
microsoft 2010-11-05
CVE-2017-0213 🔴 Łataj teraz KEV
appscloud

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…

7.3 CVSS
92.7% EPSS
CVE-2015-1701 🔴 Łataj teraz KEV
appscloud

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win…

7.8 CVSS
90.2% EPSS
CVE-2016-5195 🔴 Łataj teraz KEV
os

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, …

7.0 CVSS
94.2% EPSS
redhatexploit 2016-11-10
CVE-2013-3163 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"…

8.8 CVSS
84.5% EPSS
microsoftdos 2013-07-10
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2016-7255 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server…

7.8 CVSS
89.4% EPSS
CVE-2016-0189 🔴 Łataj teraz KEV
appscloud

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corr…

7.5 CVSS
90.8% EPSS
microsoftdosexploit 2016-05-11
CVE-2012-0151 🔴 Łataj teraz KEV
appscloud

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Pr…

7.8 CVSS
89.0% EPSS
microsoft 2012-04-10
CVE-2013-1331 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer…

7.8 CVSS
88.9% EPSS
CVE-2014-1812 🔴 Łataj teraz KEV
appscloud

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of pass…

8.8 CVSS
83.1% EPSS
CVE-2013-0641 🔴 Łataj teraz KEV
os

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February…

7.8 CVSS
88.0% EPSS
CVE-2024-7399 🔴 Łataj teraz KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

8.8 CVSS
82.3% EPSS
samsung 2024-08-12
CVE-2016-7262 🔴 Łataj teraz KEV
appscloud

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted ce…

7.8 CVSS
87.1% EPSS
microsoft 2016-12-20
CVE-2008-0015 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, …

8.8 CVSS
81.6% EPSS
CVE-2009-0557 🔴 Łataj teraz KEV
appscloud

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel View…

7.8 CVSS
86.4% EPSS
microsoft 2009-06-10
CVE-2013-3893 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrat…

8.8 CVSS
81.2% EPSS
microsoftexploit 2013-09-18
CVE-2009-0238 🔴 Łataj teraz KEV
appscloud

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 200…

8.8 CVSS
81.1% EPSS
microsoft 2009-02-25
CVE-2015-1671 🔴 Łataj teraz KEV
appscloud

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; L…

7.8 CVSS
85.9% EPSS
microsoft 2015-05-13
CVE-2017-11774 🔴 Łataj teraz KEV
appscloud

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature By…

7.8 CVSS
84.6% EPSS
microsoftexploit 2017-10-13
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2023-27351 🔴 Łataj teraz KEV

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists wi…

7.5 CVSS
86.1% EPSS
papercutauth-bypass 2023-04-20
CVE-2015-7645 🔴 Łataj teraz KEV
os

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in …

7.8 CVSS
84.5% EPSS
redhat 2015-10-15
CVE-2012-2539 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (mem…

7.8 CVSS
84.4% EPSS
microsoftdosrce 2012-12-12
CVE-2014-3120 🔴 Łataj teraz KEV
apps

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio…

8.1 CVSS
82.6% EPSS
elasticexploit 2014-07-28
CVE-2016-5198 🔴 Łataj teraz KEV
cloud

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary re…

8.8 CVSS
78.7% EPSS
googleexploit 2017-01-19
CVE-2016-4657 🔴 Łataj teraz KEV
os

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8 CVSS
78.3% EPSS
appledosexploit 2016-08-25
CVE-2015-1770 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

8.8 CVSS
78.2% EPSS
microsoft 2015-06-10
CVE-2016-0185 🔴 Łataj teraz KEV
appscloud

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Executi…

7.8 CVSS
82.8% EPSS
microsoftrce 2016-05-11
CVE-2014-4113 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

7.8 CVSS
82.4% EPSS
CVE-2017-6327 🔴 Łataj teraz KEV

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine …

8.8 CVSS
76.8% EPSS
symantecrce 2017-08-11
CVE-2016-3235 🔴 Łataj teraz KEV
appscloud

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Mi…

7.8 CVSS
81.6% EPSS
microsoftexploit 2016-06-16
CVE-2015-2424 🔴 Łataj teraz KEV
appscloud

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of servi…

8.8 CVSS
76.5% EPSS
microsoftdos 2015-07-14
CVE-2009-0556 🔴 Łataj teraz KEV
appscloud

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing…

8.8 CVSS
76.4% EPSS
microsoft 2009-04-03
CVE-2016-0984 🔴 Łataj teraz KEV

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260,…

8.8 CVSS
75.9% EPSS
adobeexploit 2016-02-10
CVE-2013-0629 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

7.5 CVSS
81.8% EPSS
adobe 2013-01-09
CVE-2013-0631 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.

7.5 CVSS
81.6% EPSS
adobe 2013-01-09
CVE-2009-0563 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Micros…

7.8 CVSS
79.9% EPSS
CVE-2017-5070 🔴 Łataj teraz KEV
cloud

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

8.8 CVSS
74.4% EPSS
googleexploit 2017-10-27
CVE-2006-2492 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object point…

8.8 CVSS
74.1% EPSS
CVE-2016-0040 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

7.8 CVSS
78.9% EPSS
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2012-5054 🔴 Łataj teraz KEV

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

8.8 CVSS
72.1% EPSS
adobeexploit 2012-09-24
CVE-2015-4495 🔴 Łataj teraz KEV
os

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector…

8.8 CVSS
71.6% EPSS
redhatexploit 2015-08-08
CVE-2008-0655 🔴 Łataj teraz KEV

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

8.8 CVSS
70.9% EPSS
adobeexploit 2008-02-07
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2010-2572 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

7.8 CVSS
74.7% EPSS
CVE-2015-2419 🔴 Łataj teraz KEV
appscloud

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability.…

8.8 CVSS
69.4% EPSS
microsoftdos 2015-07-14
CVE-2015-1642 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

7.8 CVSS
72.9% EPSS
microsoft 2015-08-15
CVE-2013-6282 🔴 Łataj teraz KEV
os

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kerne…

8.8 CVSS
67.7% EPSS
linuxexploit 2013-11-20
CVE-2010-0232 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access t…

7.8 CVSS
72.6% EPSS
microsoftdosexploit 2010-01-21
CVE-2016-1646 🔴 Łataj teraz KEV
os

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of serv…

8.8 CVSS
66.9% EPSS
redhatdosexploit 2016-03-29
CVE-2007-0671 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrat…

8.8 CVSS
66.8% EPSS
microsoft 2007-02-03
CVE-2014-0496 🔴 Łataj teraz KEV

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

8.8 CVSS
66.3% EPSS
adobe 2014-01-15
CVE-2016-7193 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 S…

7.8 CVSS
71.2% EPSS
microsoft 2016-10-14
CVE-2025-27363 🔴 Łataj teraz KEV
os

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vu…

8.1 CVSS
68.7% EPSS
debianrce 2025-03-11
CVE-2016-7256 🔴 Łataj teraz KEV
appscloud

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and …

8.8 CVSS
64.7% EPSS
microsoftrce 2016-11-10
CVE-2013-0643 🔴 Łataj teraz KEV
os

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, whic…

8.8 CVSS
64.2% EPSS
redhat 2013-02-27
CVE-2013-3660 🔴 Łataj teraz KEV
appscloud

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,…

7.8 CVSS
69.2% EPSS
microsoftexploit 2013-05-24
CVE-2014-3153 🔴 Łataj teraz KEV

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE comma…

7.8 CVSS
68.9% EPSS
suseexploit 2014-06-07
CVE-2013-2094 🔴 Łataj teraz KEV
os

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

8.4 CVSS
65.8% EPSS
linuxexploit 2013-05-14
CVE-2017-0101 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607;…

7.8 CVSS
67.2% EPSS
CVE-2011-2005 🔴 Łataj teraz KEV
appscloud

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted…

7.8 CVSS
67.1% EPSS
CVE-2017-0222 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

8.8 CVSS
62.0% EPSS
microsoftrce 2017-05-12
CVE-2016-4656 🔴 Łataj teraz KEV
os

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

7.8 CVSS
66.7% EPSS
appledosexploit 2016-08-25
CVE-2013-0648 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202…

8.8 CVSS
61.3% EPSS
redhat 2013-02-27
CVE-2010-1428 🔴 Łataj teraz KEV
os

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met…

7.5 CVSS
67.6% EPSS
redhatexploit 2010-04-28
CVE-2016-4523 🔴 Łataj teraz KEV

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

7.5 CVSS
67.0% EPSS
trihedraldos 2016-06-09
CVE-2017-0262 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
64.3% EPSS
microsoftrce 2017-05-12
CVE-2013-5065 🔴 Łataj teraz KEV
appscloud

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

7.8 CVSS
63.8% EPSS
microsoftexploit 2013-11-28
CVE-2016-7855 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil…

8.8 CVSS
57.5% EPSS
microsoft 2016-11-01
CVE-2014-4404 🔴 Łataj teraz KEV
os

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

7.8 CVSS
62.0% EPSS
CVE-2009-1862 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of se…

7.8 CVSS
58.6% EPSS
adobedos 2009-07-23
CVE-2016-0034 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web si…

8.8 CVSS
52.8% EPSS
microsoftdosrce 2016-01-13
CVE-2015-0666 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

7.5 CVSS
58.5% EPSS
ciscopath-traversal 2015-04-03
CVE-2017-1000253 🔴 Łataj teraz KEV

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 201…

7.8 CVSS
57.0% EPSS
centos 2017-10-05
CVE-2024-1708 🔴 Łataj teraz KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

8.4 CVSS
53.7% EPSS
connectwiseexploit 2024-02-21
CVE-2025-29635 🔴 Łataj teraz KEV
network

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the correspond…

7.2 CVSS
58.9% EPSS
dlinkexploitrce 2025-03-25
CVE-2014-4123 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a differ…

8.8 CVSS
50.6% EPSS
CVE-2014-0130 🔴 Łataj teraz KEV

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbin…

7.5 CVSS
57.0% EPSS
CVE-2017-5030 🔴 Łataj teraz KEV
cloud

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

8.8 CVSS
50.3% EPSS
googleexploit 2017-04-24
CVE-2014-4148 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

8.8 CVSS
49.7% EPSS
microsoftrce 2014-10-15
CVE-2016-3393 🔴 Łataj teraz KEV
appscloud

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and …

7.8 CVSS
53.1% EPSS
microsoftrce 2016-10-14
CVE-2013-1690 🔴 Łataj teraz KEV

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which al…

8.8 CVSS
47.1% EPSS
susedos 2013-06-26
CVE-2026-34197 🔴 Łataj teraz KEV
apps

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/…

8.8 CVSS
46.6% EPSS
apacherce 2026-04-07
CVE-2014-4077 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandb…

7.8 CVSS
50.8% EPSS
CVE-2024-57728 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary co…

7.2 CVSS
50.6% EPSS
simple-help 2025-01-15
CVE-2017-0210 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain…

8.8 CVSS
42.1% EPSS
CVE-2017-0149 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." …

8.8 CVSS
41.5% EPSS
microsoftdos 2017-03-17
CVE-2016-3309 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local use…

7.8 CVSS
46.3% EPSS
CVE-2015-2546 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local user…

8.2 CVSS
39.8% EPSS
CVE-2014-100005 🔴 Łataj teraz KEV
network

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) creat…

8.0 CVSS
40.8% EPSS
dlinkexploit 2015-01-13
CVE-2023-21529 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
35.0% EPSS
microsoftrce 2023-02-14
CVE-2014-8439 🔴 Łataj teraz KEV

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler be…

8.8 CVSS
34.4% EPSS
adobedos 2014-11-25
CVE-2015-2425 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a differe…

8.8 CVSS
34.1% EPSS
microsoftdos 2015-07-14
CVE-2017-11292 🔴 Łataj teraz KEV

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and su…

8.8 CVSS
33.6% EPSS
adoberce 2017-10-22
CVE-2011-1823 🔴 Łataj teraz KEV
cloud

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative in…

7.8 CVSS
38.3% EPSS
googleexploit 2011-06-09
CVE-2017-16651 🔴 Łataj teraz KEV

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017…

7.8 CVSS
37.3% EPSS
roundcubeexploit 2017-11-09
CVE-2026-21513 🔴 Łataj teraz KEV
appscloud

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

8.8 CVSS
28.0% EPSS
microsoft 2026-02-10
CVE-2016-0151 🔴 Łataj teraz KEV
appscloud

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges …

7.8 CVSS
32.4% EPSS
microsoftexploit 2016-04-12
CVE-2014-2817 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

8.8 CVSS
26.4% EPSS
CVE-2015-2502 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in t…

8.8 CVSS
22.6% EPSS
microsoftdosexploit 2015-08-19
CVE-2015-2387 🔴 Łataj teraz KEV
appscloud

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Win…

7.8 CVSS
26.6% EPSS
microsoft 2015-07-14
CVE-2026-33634 🔴 Łataj teraz KEV

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stea…

8.8 CVSS
21.1% EPSS
aquasecexploit 2026-03-23
CVE-2015-5317 🔴 Łataj teraz KEV
dev

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

7.5 CVSS
27.4% EPSS
jenkins 2015-11-25
CVE-2017-0001 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
25.4% EPSS
CVE-2017-6743 🔴 Łataj teraz KEV
network

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

8.8 CVSS
20.4% EPSS
CVE-2016-7892 🔴 Łataj teraz KEV

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

8.8 CVSS
20.2% EPSS
adoberce 2016-12-15
CVE-2016-6367 🔴 Łataj teraz KEV
network

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

7.8 CVSS
23.1% EPSS
ciscoexploit 2016-08-18
CVE-2006-1547 🔴 Łataj teraz KEV
apps

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the …

7.5 CVSS
22.2% EPSS
apachedosexploit 2006-03-30
CVE-2015-1130 🔴 Łataj teraz KEV
os

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

7.8 CVSS
20.4% EPSS
CVE-2026-21533 🔴 Łataj teraz KEV
appscloud

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

7.8 CVSS
19.6% EPSS
microsoft 2026-02-10
CVE-2017-6737 🔴 Łataj teraz KEV
network

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a …

8.8 CVSS
14.1% EPSS
CVE-2017-6738 🔴 Łataj teraz KEV
network

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

8.8 CVSS
14.1% EPSS
CVE-2017-6739 🔴 Łataj teraz KEV
network

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a …

8.8 CVSS
14.1% EPSS
CVE-2017-0263 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local…

7.8 CVSS
18.5% EPSS
CVE-2016-1010 🔴 Łataj teraz KEV

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Ado…

8.8 CVSS
12.7% EPSS
adobe 2016-03-12
CVE-2016-8562 🔴 Łataj teraz KEV

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which sho…

7.5 CVSS
18.6% EPSS
siemens 2016-11-18
CVE-2015-2360 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi…

8.8 CVSS
11.6% EPSS